OneSpaAI recognizes the importance of data privacy and respects your right to control your personal information. This comprehensive Data Deletion Policy outlines the strict procedures, timelines, and responsibilities governing the removal of personal data from our software infrastructure.
To accurately process data deletion requests, it is critical to understand OneSpaAI's legal role. OneSpaAI acts strictly as a Data Processor (or Service Provider) for the independent spas, salons, and wellness businesses that utilize our software. The independent businesses themselves act as the Data Controllers. If you are an end-user (a client who booked a service at a spa/salon), your data is legally controlled by that business. OneSpaAI only processes this data to facilitate their operations. Therefore, primary requests regarding service records, local marketing opt-outs, and complete profile deletion must be directed to the specific business you interacted with.
If you hold a direct account with OneSpaAI (e.g., you are a spa/salon business owner) or if you wish to request the deletion of residual data stored on our central cloud infrastructure, you may submit a formal data deletion request. All requests must be submitted in writing via email to tech[at]onespaai[dot]com. We reserve the right to verify your identity before processing any deletion request to prevent unauthorized data removal.
Upon receiving a verified and legally valid data deletion request, OneSpaAI will execute the following procedures:
Please be advised that certain data may be exempt from immediate deletion requirements under applicable laws. OneSpaAI reserves the right to retain specific data elements where necessary to:
To ensure business continuity and disaster recovery, OneSpaAI maintains secure, encrypted system backups. When a deletion request is processed, data is removed from our active databases immediately. However, it is technically infeasible to surgically remove individual records from immutable backup archives. Therefore, your data may temporarily persist in our backup systems until those backups are automatically overwritten and destroyed in accordance with our standard data retention lifecycle (typically 60 to 90 days). During this period, backup data remains strictly inaccessible for operational processing.